Context.ai OAuth Token Compromise: SaaS Integration-Layer Supply Chain Attack — Threadlinqs Intelligence
As of 2026-05-30, Context.ai OAuth Token Compromise: SaaS Integration-Layer Supply Chain Attack is a critical-severity supply chain threat attributed to UNC6438 (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0398 · Severity: CRITICAL · CVSS: 9.1 · Status: MONITORING · Category: SUPPLY_CHAIN
Attribution: UNC6438 · N/A · FINANCIAL
Attackers stole OAuth refresh tokens issued to Context.ai, a SaaS data-ingestion platform, and abused the trust relationships to pivot into downstream customer tenants via connected Salesforce,
On 2026-04-19, Wiz Threat Research identified anomalous API traffic originating from Context.ai infrastructure ranges against multiple unrelated Salesforce and Google Workspace customer tenants. Investigation determined that on or about 2026-04-08 an unknown actor obtained access to Context.ai's production secrets management system (HashiCorp Vault) via a compromised GitHub Actions workflow that logged a long-lived personal access token to a public build artifact. The actor used the Vault access to enumerate and exfiltrate the OAuth refresh tokens Context.ai had accumulated for every customer-granted integration, approximately 3,400 active refresh tokens covering Salesforce (T1199), HubSpot, Slack, Google Workspace, Microsoft 365, Notion, Zendesk, and GitHub.
For ~11 days the actor used these tokens from a rotating pool of residential proxy IPs (NSOCKS, 911 S5 successor) and datacenter ranges in Hetzner, OVH, and DigitalOcean to issue legitimate-looking API calls against each downstream tenant. Because the tokens were valid and scoped as the tenant had originally authorized (typical scopes: read:all-contacts, read:all-deals, read:drive.readonly, channels:history, files:read), the traffic passed authentication and logged as Context.ai activity in each tenant's audit log — there was no malware, no phishing, and no unusual login from the end-user perspective.
Exfiltration targeted three data classes: (1) CRM records (Salesforce accounts, opportunities, contacts — particularly from Context.ai customers in the defense, fintech, and healthcare verticals), (2) Slack DMs and private channel history for executive and security-team conversations, and (3) Google Drive documents matching regex patterns for API keys, AWS credentials, and SSO SAML signing certificates. Wiz observed at least 14 victim tenants from which secondary compromise followed — attackers used Drive-harvested AWS keys to provision compute in victim AWS accounts, and used harvested SAML signing certificates to forge session tokens for downstream SaaS apps (Golden SAML pattern, T1606.002).
Context.ai rotated all OAuth refresh tokens and revoked customer integrations on 2026-04-19, forcing every customer to re-authorize. CISA issued an alert the same day urging all Context.ai customers to (a) audit OAuth-connected applications in each SaaS tenant for the Context.ai app and revoke if unused, (b) review 30 days of API activity for the Context.ai application against the published IOC ranges, and (c) rotate any credentials, certificates, or tokens that may have been stored in connected Google Drive, SharePoint, or Notion workspaces.
The incident is representative of a growing class of SaaS integration-layer supply chain attacks (analogues: Okta support breach 2023, Snowflake credential abuse 2024, Midnight Blizzard / Microsoft OAuth 2024). It does not correspond to a software CVE — there is no vulnerable version to patch — and detection relies entirely on SaaS audit-log anomaly analytics, OAuth app inventory hygiene, and rigorous data-access scope review.
Weaknesses (CWE)
CWE-798, CWE-522, CWE-287, CWE-552, CWE-1391
Target sectors: technology, financial, healthcare, defense, professional-services, saas
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1583, T1583.008, T1199, T1078.004, T1528, T1552.001, T1552.005, T1550.001, T1606.002, T1526